Email Deliverability: SPF, DKIM, and DMARC with Postfix
Getting your emails into the inbox instead of the spam folder can be tricky. I'll walk you through setting up SPF, DKIM, and DMARC with Postfix, the basics I use on my servers to improve email deliverability.
On this page
Getting emails into the inbox, not spam, is a constant battle. I've spent a lot of time tweaking things on my servers to improve deliverability for my clients and my own projects. A big part of that is setting up SPF, DKIM, and DMARC correctly with Postfix. Let's go through the steps.
SPF (Sender Policy Framework)
SPF tells receiving servers which mail servers are allowed to send emails on behalf of your domain. Without it, spammers can easily spoof your domain, and your emails get flagged as spam.
- Create the SPF record: I usually create a TXT record in my DNS settings for my domain (e.g.,
example.com). The record looks something like this:
"v=spf1 mx a ip4:192.168.1.10 include:example.com ~all"
v=spf1: Specifies the SPF version.mx: Allows servers listed in your MX records to send emails.a: Allows servers listed in your A records to send emails.ip4:192.168.1.10: Allows a specific IP address to send emails (replace with your server's IP).include:example.com: Includes SPF records from another domain (useful if you use a third-party email service).~all: Soft fail, receiving servers should treat emails from unauthorized servers with caution.–allis a hard fail (more strict, but can cause issues).
- Test your SPF record: Use online tools like MXToolbox SPF Record Lookup to check if your SPF record is valid and propagating correctly.
DKIM (DomainKeys Identified Mail)
DKIM adds a digital signature to your emails, which verifies that the content hasn't been altered in transit. This is a bit more involved than SPF.
- Generate a DKIM key: I use
opensslto generate a private and public key. This command will create a 2048-bit key (more secure than the default):
openssl genrsa -out /etc/postfix/dkim.example.com.key 2048
openssl rsa -in /etc/postfix/dkim.example.com.key -pubout -out /etc/postfix/dkim.example.com.pub
- Configure Postfix for DKIM: Edit your
main.cffile (usually located at/etc/postfix/main.cf): Ubuntu 24.04 uses this format.
dkim_enable = yes
dkim_domain = example.com
dkim_selector = example
dkim_identity = [email protected]
dkim_key_file = /etc/postfix/dkim.example.com.key
dkim_signing_table = hash:/etc/postfix/dkim_signing_table
dkim_domain: Your domain name.dkim_selector: A unique identifier for your DKIM key (can be anything, but I use the domain name here).dkim_identity: The email address used to sign the emails.dkim_key_file: Path to your private key.dkim_signing_table: Specifies which emails to sign.
- Create the signing table: Create a file (e.g.,
/etc/postfix/dkim_signing_table) and add entries like this:
@example.com /etc/postfix/dkim.example.com.key
This signs all emails from @example.com with the specified key. Then, create a lookup table:
postmap /etc/postfix/dkim_signing_table
-
Add the public key to DNS: Get the public key from
/etc/postfix/dkim.example.com.pub. Create a TXT record in your DNS settings with a name likeexample._domainkey.example.comand paste the public key into the value. This is important! -
Reload Postfix:
systemctl reload postfix
DMARC (Domain-based Message Authentication, Reporting & Conformance)
DMARC builds on SPF and DKIM. It tells receiving servers what to do with emails that fail SPF and DKIM checks. It also allows you to receive reports about email authentication failures.
- Create the DMARC record: Create a TXT record in your DNS settings for
_dmarc.example.comwith a record like this:
"v=DMARC1; p=none; rua=mailto:[email protected]"
v=DMARC1: Specifies the DMARC version.p=none: Policy,none(monitor mode),quarantine(send to spam), orreject(reject the email).rua=mailto:[email protected]: Aggregate reporting address, where to send DMARC reports.
- Monitor DMARC reports: The
ruaaddress will receive XML reports. These reports can be complex, but they provide valuable insights into your email authentication setup. There are online tools to help parse these reports. I usually start withp=noneto monitor and adjust before enforcing a stricter policy.
My setup
On my servers, I prefer to use a DKIM selector that matches the domain name. This makes it easier to manage multiple DKIM keys if needed. I also always test my SPF, DKIM, and DMARC records using online tools after making changes. Forgetting to reload Postfix (systemctl reload postfix) is a common mistake, make sure you do it after any configuration changes!
What went wrong (gotchas)
- Incorrect DNS propagation: DNS changes can take time to propagate. Be patient and use online tools to verify propagation.
- Incorrect key paths: Double-check the paths to your private and public keys in the Postfix configuration.
- Missing DMARC record: Without a DMARC record, you're not taking full advantage of the system.
- Conflicting SPF records: Make sure you don't have multiple SPF records for the same domain.
- SELinux: If you're using SELinux, you might need to adjust the contexts for your DKIM keys. This is less common on Debian, but it's something to watch out for on CentOS/AlmaLinux. I usually check the file contexts with
ls -lZ /etc/postfix/.
Setting up SPF, DKIM, and DMARC can be a bit complex, but it’s essential for improving email deliverability. It's a worthwhile investment of time for anyone serious about email communication.
I find it's well worth the effort, getting emails directly to the inbox is a much better experience for everyone. See my server hardening checklist for other steps you can take to secure your server.
Related reading
Frequently asked questions
Why are SPF, DKIM, and DMARC important?
They're like digital signatures for your emails. They tell receiving mail servers that you're authorized to send emails on behalf of your domain, helping to prevent spoofing and improve deliverability. Without them, your emails are more likely to end up in spam.
What's the difference between SPF, DKIM, and DMARC?
SPF verifies the sending server, DKIM verifies the email content hasn't been tampered with, and DMARC tells receiving servers what to do with emails that fail SPF and DKIM checks. They work together for maximum protection.
How long does it take for these changes to take effect?
It varies! Some servers will pick up the changes quickly, but it can take up to 48 hours (or even longer) for all receiving servers to update their records. Be patient and monitor your email delivery.